Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Director

previous version on gdrive

A.8.2 Privileged Access Rights

Control Objective

The allocation and use of privileged access rights shall be restricted and managed.

Policy Statement

anDREa strictly limits and governs the assignment of privileged access rights across all platform, corporate, and client boundaries. Privileged rights are granted based on the principle of least privilege, require mandatory prerequisite training, and are subjected to continuous authorization monitoring and just-in-time activation controls to prevent unauthorized configuration changes or data exposure.


1. Personnel & Research Support Team (RST) Governance

Privileged administrative access to core environments is managed through tight verification and onboarding guardrails:

  • Least-Privilege Allocation: Access to internal systems is provisioned exclusively by the designated Asset Owner. A comprehensive matrix of active environments, along with the specific technical permissions allocated to each individual, is maintained within Asset Overview.
  • Mandatory Training: Internal users slated for privileged access roles within the anDREa Entra ID tenant must successfully complete specialized training via the anDREa People HR before permissions are applied.
  • Customer Support Integration (RST): * The internal support team creates federated guest accounts within anDREa Entra ID for authorized customer Research Support Team (RST) members.
    • anDREa is directly responsible for training these external engineers before provisioning access to Entra ID or the corporate ticketing architecture.
  • Prerequisites for RST Access: Candidate RST members are registered in myDRE People Platform, must review the Research Support Profile, formally execute and pass the RST Training Quiz.
note

anDREa B.V. acts solely as an infrastructure/tenant provider and is explicitly not involved in day-to-day workspace creation, end-user account submissions, or inviting research users to individual Workspaces.*


2. Technical Privileged Access Management (PAM)

To reduce the blast radius of administrative credentials, anDREa relies on dynamic identity orchestration:

  • Just-In-Time (JIT) Elevation: Operating within the core anDREa Entra ID tenant requires administrative personnel to explicitly request and activate their roles through Azure Privileged Identity Management (PIM) and myDRE Privileged Access Management (PAM). Permanent, always-on administrative privileges are strictly prohibited and disabled.
  • Continuous Auditing: PIM activation logs and elevation metrics are formally reviewed on a monthly basis. Any anomalies, excessive elevation windows, or compliance deviations are escalated directly to the bi-monthly Information Security Management Board (ISMB) Meetings for investigation.

3. Customer & Corporate Access Segmentation

  • myDRE Platform End Users: General platform users are entirely isolated within their specific project boundaries. They are granted access exclusively to Workspaces where they possess active memberships. Permissions within those environments are handled via pre-configured Role-Based Access Control (RBAC) (see Roles in myDRE workspace), under the sole authorization authority of the Workspace Accountable Member.
  • anDREa Corporate End Users: Internal personnel are restricted to the precise files, directories, and SaaS platforms required to fulfill their job descriptions. Access is controlled via Group-level RBAC. Highly sensitive environments or root administrative consoles can only be accessed using an authenticated corporate @andrea-cloud.com identity.